Splunk Search

Splunk Search
Community Activity
childroland
I am trying to build a query to find outliers using avg and stdev on a perfmon counter but the counter is not a value...
by childroland Explorer in Splunk Search 01-02-2020
0 11
0
11
unitedmarsupial
Suppose, one has an alert defined for checking multiple application-instances. Can the actions defined for the alert...
by unitedmarsupial Path Finder in Splunk Search 01-02-2020
0 11
0
11
disillusioned
I have a search: index=lab-testresults sourcetype=lab-testresults type=testCase and inside of the testCase I have a f...
by disillusioned New Member in Splunk Search 01-02-2020
0 2
0
2
vwilson3
Greetings, I've been trying to tweak an inherited report to only show the results where the count of events is blank...
by vwilson3 Path Finder in Splunk Search 01-02-2020
0 5
0
5
palisetty
I have sum (field) which has been piped into stats sum of another field, Not sure what is happening here. Kindly help...
by palisetty Communicator in Splunk Search 01-02-2020
0 7
0
7
matt1t
All, I've been banging my head against the wall on this. Maybe its not possible, I don't know. I'm doing a multi se...
by matt1t Explorer in Splunk Search 01-02-2020
0 2
0
2
Deprasad
I have a report generated with following fields, Field 1 , Field 2, Field 3. I have to create an alert based on the...
by Deprasad Path Finder in Splunk Search 01-02-2020
0 2
0
2
palisetty
@gcusello I have multiple count functions in the same search component. What does it mean by that? What is really ha...
by palisetty Communicator in Splunk Search 01-02-2020
0 1
0
1
tahasefiani
Hi everyone, I'm trying this search but apparently Splunk doesn't have the same logic as SQl. Can someone give me he...
by tahasefiani Explorer in Splunk Search 01-02-2020
0 3
0
3
jlkokko
I have the following search: index="main" |rename Proj_repo AS Project | multireport [ stats values(Project) AS Proj...
by jlkokko Path Finder in Splunk Search 01-02-2020
0 7
0
7
palisetty
(T/F) Using NOT and != would return the same results. For me, the answer is false but quizlet says true. I say false ...
by palisetty Communicator in Splunk Search 01-01-2020
1 4
1
4
stephenreece
Hi all, hope there is a way to do the following. I am trying to find out how many events it takes for a user to go f...
by stephenreece New Member in Splunk Search 01-01-2020
0 8
0
8
bhavya49
{ [-] detailMap: { [-] critical: false result: 0 totalCnt: 5 txnCountWithIgnoredIRC: 0 wa...
by bhavya49 New Member in Splunk Search 01-01-2020
0 2
0
2
palisetty
Search terms are case sensitive or case insensitive? (components of search language)? For me, the answer is case sen...
by palisetty Communicator in Splunk Search 01-01-2020
0 9
0
9
mitag
The goal is to generate a new field "Category" and assign it an arbitrary value (e.g. "Error") depending on which reg...
by mitag Contributor in Splunk Search 12-31-2019
0 4
0
4
sbgoldberg13
I have the following 2 alerts and need to correlate them. The first one is looks for an OS reboot. The second one l...
by sbgoldberg13 Explorer in Splunk Search 12-31-2019
0 5
0
5
patrick112
I'm trying to automate the deployment of the Heavy Forwarder, as part of that i'm automatically fetching the Splunk H...
by patrick112 New Member in Splunk Search 12-31-2019
0 0
0
0
UMDTERPS
| eval nessus = if(like(nessus, "%2019") AND relative_time(now(), "-30d@d") < strptime(nessus,"%m/%d/%Y"), 1, 0) Ab...
by UMDTERPS Communicator in Splunk Search 12-31-2019
0 2
0
2
dchoi_splunk
When we set up Splunk to start under systemd it prompts us recursively for the root password even we're running Splun...
by dchoi_splunk Splunk Employee Splunk Employee in Splunk Search 12-31-2019
0 5
0
5
danielbb
On our primary search head max_searches_per_cpu is set to 6. I wonder if it’s a good effective set-up. Where can I fi...
by danielbb Motivator in Splunk Search 12-31-2019
0 7
0
7
russell120
I'm using the following search with timechart span=1h to show how many events appear by the day and hour: |inputlook...
by russell120 Communicator in Splunk Search 12-31-2019
0 7
0
7
UMDTERPS
Hello, Currently we have a scoring for our systems that counts each server, router, switch, firewall, workstation, e...
by UMDTERPS Communicator in Splunk Search 12-31-2019
0 8
0
8
lucas4394
We found there were some savedsearches deleted for some reasons. Is it a way to find out who deleted the savedsearch...
by lucas4394 Path Finder in Splunk Search 12-31-2019
0 2
0
2
rakesh635
I am using jenkins's splunk plugin version 1.6.3(latest). I have configured no executor in master, so no possibility ...
by rakesh635 Engager in Splunk Search 12-31-2019
3 14
3
14
yepyepyayyooo
Greetings good people, i may be over thinking things or didn't get enough sleep. I need to return results where a fi...
by yepyepyayyooo New Member in Splunk Search 12-30-2019
0 6
0
6
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...